Stars
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Java web common vulnerabilities and security code which is base on springboot and spring security
一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.
Jar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等
Share Things Related to Java - Java安全漫谈笔记相关内容
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways. 信息洞察,智探千方!
攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
NSFOCUS API_Sword:A Burp Suite extension, Automatically recursively collect API endpoints from any response
Burpsuite - Js Route Scan 正则匹配获取响应中的路由进行被动探测与递归目录探测的burp插件
Burp插件,Malleable C2 Profiles生成器;可以通过Burp代理选中请求,生成Cobalt Strike的profile文件(CSprofile)